CVE-2025-50614

7.5

Netis · WF2880 v2

A buffer overflow in the Netis WF2880 v2 cgitest.cgi file, specifically the FUN_0047151c function, allows unauthenticated remote attackers to trigger a Denial of Service via a crafted wds_set parameter.

Executive summary

A critical buffer overflow vulnerability in the Netis WF2880 v2 router allows unauthenticated attackers to cause a system crash and Denial of Service.

Vulnerability

This vulnerability is a buffer overflow located in the FUN_0047151c function within the cgitest.cgi file. The flaw is reachable by an unauthenticated attacker who provides a malicious payload via the wds_set parameter, leading to a service crash.

Business impact

Successful exploitation of this vulnerability results in a Denial of Service, rendering the affected network device unresponsive. With a CVSS score of 7.5, this high severity flaw poses a significant risk to network availability and business continuity, particularly for organizations relying on this hardware for edge connectivity.

Remediation

Immediate Action: Since no official patch is currently available, administrators should restrict access to the web management interface of the Netis WF2880 v2, ensuring it is not exposed to the public internet.

Proactive Monitoring: Monitor device logs and network traffic for unusual spikes in requests directed toward the cgitest.cgi endpoint or frequent device reboots.

Compensating Controls: Deploy a Web Application Firewall or an Access Control List to block or sanitize traffic containing suspicious wds_set parameters directed at the management interface.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research write-up referenced by the CVE Program.

Analyst recommendation

Given the availability of a public proof-of-concept and the potential for remote service disruption, immediate action is required to isolate affected devices from external network access. Organizations should prioritize disabling remote management features until a vendor-supplied firmware update addressing the buffer overflow is released and applied.

More Netis CVEs

Sources